HIPAA Security Rule To Strengthen the Cybersecurity of Electronic Protected Health Information
HHS proposes to strengthen HIPAA Security Rule cybersecurity requirements for ePHI, with new mandates for asset inventory, risk analysis, encryption, multi-factor authentication, and more. Comments due by March 7, 2025.
Aforeworn detected this change in the Healthcare AI Regulation (FDA / ONC) space on July 29, 2026 and published this briefing so affected operators are forewarned rather than caught off guard. It is rated High urgency. All HIPAA-covered entities and business associates that create, receive, maintain, or transmit electronic protected health information (ePHI), including health systems, medical device companies, health tech startups, and digital health compliance teams. should confirm how it applies to their specific situation before acting. There is a time constraint attached: Comments due March 7, 2025 (60 days after publication on January 6, 2025).. Acting after that point can mean penalties, a lapsed licence, or lost eligibility — exactly the kind of surprise Aforeworn exists to prevent. Aforeworn monitors Healthcare AI Regulation (FDA / ONC) continuously and turns every detected change into a plain-English briefing like this one, so you always know first. Forewarned is forearmed.
What changed
The proposed rule would require: (1) a written asset inventory and network map; (2) updated risk analysis including all ePHI systems; (3) encryption of ePHI at rest and in transit; (4) multi-factor authentication for any system accessing ePHI; (5) vulnerability scanning and penetration testing; (6) audit controls and logging; (7) contingency plan testing; (8) annual compliance audits; and (9) 24-hour breach notification to HHS. No specific dollar amounts or penalties are stated in the excerpt.
Who it affects
All HIPAA-covered entities and business associates that create, receive, maintain, or transmit electronic protected health information (ePHI), including health systems, medical device companies, health tech startups, and digital health compliance teams.
What you must do
Review the full NPRM and submit comments by the deadline. Begin gap analysis against proposed requirements to prepare for eventual compliance.
Deadline
Comments due March 7, 2025 (60 days after publication on January 6, 2025).
Never miss a change like this again
Aforeworn watches Healthcare AI Regulation (FDA / ONC) around the clock and alerts you the moment a rule moves — with a plain-English brief on what to do.
Start your free trialRelated changes in Healthcare AI Regulation (FDA / ONC)
- Medical Devices; General Hospital and Personal Use Devices; Classification of the Diabetes Digital Behavioral Therapeutic Device
- Health Data, Technology, and Interoperability: ASTP/ONC Deregulatory Actions To Unleash Prosperity
- Nondiscrimination in Health Programs and Activities
- Health Data, Technology, and Interoperability: Certification Program Updates, Algorithm Transparency, and Information Sharing
- Marketing Submission Recommendations for a Predetermined Change Control Plan for Artificial Intelligence-Enabled Device Software Functions; Guidance for Industry and Food and Drug Administration Staff; Availability